Announcement

Collapse
No announcement yet.

Add Device / Mount Drive (Anomalie)

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Add Device / Mount Drive (Anomalie)

    Hi there,

    today I added a device (encase image file) to my case. The dialog showed 3 partitions to select.

    Partition 0 - 94.1 MB,
    Partition 1 - 143.7 GB and
    Partition 2 - 2.0 GB.

    When I mounted the drive as a new virtual disk I suddently discovered 4 partitions on the device:

    Primary partition 1 - 94.1 MB Unknown
    Primary partition 2 - 143.7 GB NTFS
    Primary partition 4 - 3.302 GB Unknown
    Logical partition 1 - 1.999 GB Unknown

    Any idea what´s going on here?

    best regards
    Last edited by Forensik; Sep-10-2012, 02:25 PM.

  • #2
    It looks like the layout of your image file is as follows:

    Primary partition 1 - 94.1 MB
    Primary partition 2 - 143.7 GB
    Primary partition 3 (Extended partition: Logical partition 1) - 1.999 GB
    Primary partition 4 - 3.302 GB

    Primary partition 4 seems to be an empty/unrecognisable partition.

    In the case of OSFMount, all partitions are displayed despite the partition being empty/unrecognisable.

    When adding an image file to the case in OSF, only non-empty/recognisable partitions are displayed in the selection box. Because Primary partition 4 was an unrecognisable partition type, it was omitted from the selection box. We will change this behaviour in our next release to display all partitions as it would be better for forensic purposes.

    Comment

    Working...
    X